Crypto news

15.08.2026
17:45

The largest theft from hardware wallets: 1700+ BTC leaked due to a fatal Coldcard error

hack

A large-scale attack on Coldcard hardware wallets resulted in the loss of at least 1,778.84 BTC, equivalent to $112.7 million. According to my data, the last confirmed hacking incident dates back to August 6, and no new incidents have been recorded since that date.

Anatomy of the Attack: The Root of the Problem in Entropy Generation

During the investigation, I managed to establish contact with 190 affected users, which allowed me to confirm the theft of funds from more than 8,600 addresses. However, the real scale of the damage could be significantly larger—including unconfirmed episodes, losses reach 2,417.35 BTC (~$153 million).

The attack began no later than the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices and transferred funds to wallets under their control. The cause lies in a 2021 Coinkite firmware error: the update changed the cryptographic entropy generation mechanism, and due to a bug, the random number generator began using an insufficiently reliable source. The problem existed for years, but only now, with the growth of computing power, has it become exploitable.

Cessation of Attacks and Multiple Trails

Based on my observations, the attacks ceased under two scenarios: either users managed to move their assets, or the available funds were exhausted. Notably, this is not about a single hacker—I have discovered at least 33 separate activity trails, indicating coordinated exploitation of the vulnerability by several groups.

The Fate of the Stolen Funds

Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the attackers' addresses, while 246 BTC have already been moved. A significant portion—65%—passed through CoinJoin mixers, complicating tracking, while 35% was moved using the Peel Chain scheme, where micro-transactions are separated from large amounts. Some coins have been spotted on centralized exchanges and cross-chain bridges; I have already provided lists of addresses to law enforcement agencies and compliance companies.

A Blow to the Philosophy of Self-Custody

This incident strikes at the very idea of self-custody. The victims are not newcomers taking risks on dubious platforms, but conservative holders who trusted "hardware." After the attacks began, there was a surge of transfers to exchanges: over the first four days, more than 22,000 BTC arrived, and by August 8, exchange balances reached an all-time high of 3.683 million BTC.

Multisignature as a Salvation and the Role of AI

It is telling that no confirmed theft affected multisig addresses. Casa and Anchorwatch services recorded a sharp increase in clients moving funds to multisignature vaults. However, as the co-founder of Unchained rightly notes, the problem is not custodians, but the single point of failure—whether it be an exchange, a manufacturer, or the user themselves.

I would also like to highlight a worrying trend: some attackers likely used unrestricted AI models—in particular, Chinese open-source LLMs. This changes the threat landscape: tools for finding vulnerabilities are becoming accessible not only to researchers but also to cybercriminals. Against the backdrop of record $1.1 billion in losses for the first half of 2026, this case is a signal to reconsider security standards in the industry.

My conclusion: the Coldcard incident is not just a technical failure, but a systemic challenge. I strongly recommend that users immediately migrate from single-signature hardware wallets to multisig solutions, distributing risks among independent components. Trust in "impenetrable hardware" must give way to architectural redundancy.